#DNSSEC

Julian :rainbow_heart:Loredo@chaos.social
2026-02-01

Enabling #DNSSEC is easy as cake with PowerDNS. Just a copy & paste to INWX’s domain management console and that’s it.

Enabling DANE for my e-mail server was easy afterwards as well. There is no reason today not to have it :-)

Stéphane Bortzmeyerbortzmeyer@mastodon.gougere.fr
2026-02-01

First time I see #DNSSEC signatures with a validity period of only a few minutes…

mastodon.gougere.fr/@bortzmeye

Stéphane Bortzmeyerbortzmeyer@mastodon.gougere.fr
2026-02-01

And this log can now be queried through #DNS mastodon.gougere.fr/@DNSresolv

(and with #DNSSEC authentication)

Built with the excellent Go DNS library github.com/miekg/dns

#FOSDEM

Stéphane Bortzmeyerbortzmeyer@mastodon.gougere.fr
2026-02-01

For #DNSSEC, the domain crate can use different crypto backends such as the ring crate or the #OpenSSL bindings. (But there are more.)

There is now a common-line tool to query the DNS, dnsi. And a CLI tool to do misc. manipulations, dnst ("people are using the ldns library example programs in production"). And a key manager, keyset.

#FOSDEM

Stéphane Bortzmeyerbortzmeyer@mastodon.gougere.fr
2026-02-01

We start with #Rust: last news of the domain crate.

First big user of this library is #Cascade, the #DNSSEC signer.

#FOSDEM #DNS

Patrick Cernkoerrror
2026-02-01

@ruawhitepaw is also missing DNS records and , which would help protect there users accessing it via git over SSH!

Michaela Molthagenmichaela@mstdn.molthagen.de
2026-01-31

Meh. FairEmail weigert sich mal wieder, sich bei erzwungener DANE-Validierung mit meinem Mail-Server zu verbinden.

Die im TLSA-Record hinterlegten Signaturen seien angeblich nicht gültig. Sind sie aber.

#FairEmail #DANE #DNSSEC

Wouter Kobeswouterkobes
2026-01-31

@koen @fediversity heel tof! Kunnen jullie ook DNSSEC inschakelen voor pixelfed.com (na FOSDEM 😉). Zie internet.nl/site/pixelfed.com/

@internet_nl

Jerry Lundströmjelu@mastodns.net
2026-01-30

#validns v0.9.0 released!
- Support for WALLET and ZoneMD RR types
- Root zone membership check now correctly allows TLDs
- Report when DNSSEC signature algorithms are disabled by policy
- Several segfaults and code analysis issues fixed
and more, see full changelog for details!
#DNS #DNSSEC #Zone #Validation #OpenSource
codeberg.org/DNS-OARC/validns/

JP Mensjpmens
2026-01-30

I wrote up something along these lines a few years ago using terminology from a presentation I had admired. Not specifically bound (pun!) to BIND9.

jpmens.net/2022/09/22/dnssec-s

JP Mensjpmens
2026-01-30

This article describes how to configure and operate BIND 9 with an offline KSK. Offline KSK was introduced in BIND 9.20.2, with support for KSK rollover in this mode added in 9.20.4

kb.isc.org/docs/dnssec-signing

We need to simplify client certificates for IoT and MTLS. One way is to anchor client certs in DNS.
The IETF DANCE working group needs more energy to complete our work. Want to join? Get on the mailing list now and help out!
datatracker.ietf.org/group/dan

#PKI #DNSsec #MTLS #IOT

Petr Menšík :fedora:pemensik@fosstodon.org
2026-01-23

Visited #CSNOG26 conference, it was great event. I had to disable #DNSSEC validation on their wifi network. Asked for a contact to local network admin to ask what is the implementation used. Surprise, they said #bind9. If you operate anything old enough capable of ``dnssec-enabled no;``, please don't use it anyway. Use ``dnssec-validation no;`` only. It will stop servfail caused by validation failures, but won't prevent validation at clients. Fix your forwarders or firewalls if that is not ok

Paul Wouters 🇪🇺🇨🇦letoams@defcon.social
2026-01-22

I talked recently about #dnssec with someone about .de and lack of updated algorithms but I can’t find the thread anymore. If that was you please ping me 😀

Dan Yorkdanyork
2026-01-21

Are you doing something interesting with , , routing security, or other forms of security that you would like to share with the wider (DNS-related) technical community?

If so, consider submitting a proposal for the "DNSSEC and Security Workshop" that will be held at ICANN 85 in Mumbai in March 2026.

Deadline is January 30. Note that you do NOT have to be in Mumbai (I will not be) - you can present remotely.

Details at: circleid.com/posts/call-for-pa

Petr Menšík :fedora:pemensik@fosstodon.org
2026-01-21

Na návštěvě #csnog jsem musel vypnout #dnssec validaci, abych se dostal na WiFi. Trochu zamrzí, že zrovna na setkání síťařů to je potřeba. Chyběl funkční dnssec-trigger. Snad příští rok už to bude umět #dnsconfd automaticky zjistit.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst